Show filters
47 Total Results
Displaying 41-47 of 47
Sort by:
Attacker Value
Unknown
CVE-2016-3141
Disclosure Date: March 31, 2016 (last updated November 08, 2023)
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.
0
Attacker Value
Unknown
CVE-2015-6832
Disclosure Date: January 19, 2016 (last updated November 08, 2023)
Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers misuse of an array field.
0
Attacker Value
Unknown
CVE-2015-6833
Disclosure Date: January 19, 2016 (last updated November 08, 2023)
Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.
0
Attacker Value
Unknown
CVE-2016-1903
Disclosure Date: January 19, 2016 (last updated November 25, 2024)
The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.
0
Attacker Value
Unknown
CVE-2015-6836
Disclosure Date: January 19, 2016 (last updated November 08, 2023)
The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.
0
Attacker Value
Unknown
CVE-2015-7803
Disclosure Date: December 11, 2015 (last updated October 05, 2023)
The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.
0
Attacker Value
Unknown
CVE-2015-7804
Disclosure Date: December 11, 2015 (last updated October 05, 2023)
Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.
0